3-9
To do…
Use the command…
Remarks
Create a local user and
enter local user view
local-user
user-name
No local user exists by default.
Set the authentication
password for the local user
password
{
simple
|
cipher
}
password
Required
By default, a user is authorized with
no password
Specifies the level of the
local user
authorization-attribute
level level
By default, no authorization attribute is
configured for a local user
Specify the service type for
AUX users
service-type telnet
Required
By default, a user is authorized with
no service
Note that, when you log in to an Ethernet switch using the scheme authentication mode, your access
rights depend on your user level defined in the AAA scheme.
When the local authentication mode is used, the user levels are specified using the
authorization-attribute level level
command.
When the RADIUS or HWTACACS authentication mode is used, the user levels are set on the
corresponding RADIUS or HWTACACS servers.
For more information about AAA, RADIUS, and HWTACACS, see
AAA Configuration
in the
Security
Volume
.
Configuration Example
1) Network
requirements
Assume that you are a level 3 AUX user and want to perform the following configuration for Telnet users
logging in to VTY 0:
z
Configure the name of the local user to be “guest”.
z
Set the authentication password of the local user to 123456 (in plain text).
z
Set the service type of VTY users to Telnet.
z
Configure to authenticate users logging in to VTY 0 in scheme mode.
z
The commands of level 2 are available to users logging in to VTY 0.
z
Telnet protocol is supported in VTY 0.
z
The screen can contain up to 30 lines.
z
The history command buffer can store up to 20 commands.
z
The timeout time of VTY 0 is 6 minutes.
2) Network
diagram